Security Assessment: CVEs related to moment.js in Workload Control Center (WCC)
search cancel

Security Assessment: CVEs related to moment.js in Workload Control Center (WCC)

book

Article ID: 446966

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

 

Clients or security scan tools may raise concerns regarding the following CVEs related to the third-party moment.js library:

  • CVE-2016-4055

  • CVE-2017-18214

  • CVE-2022-24785

  • CVE-2022-31129

In WCC 12.1.x environments, running strings against the file /opt/CA/WorkloadAutomationAE/wcc/tomcat/webapps/quickview/scripts/moment.min.js reveals that it utilizes version 2.23.0. Per the National Vulnerability Database (NVD), upgrading moment.js to version 2.29.4 or higher is required to clear all version-level vulnerability findings.

As there are no specific standalone security patches addressing this for the 12.1.x release line, users want to know if upgrading to WCC 24.2 (which bundles version 2.30.1) is the only method of remediation.

 

Environment

Workload Control Center (WCC) 12.1.x (e.g., 12.1 SP1 CUM4)

Workload Control Center (WCC) 24.2

Resolution

A detailed security review of the moment.js library (version 2.23.0) bundled within WCC 12.1.x indicates that the application is not vulnerable to exploitation for any of the four reported CVEs.

  • CVE-2016-4055 and CVE-2017-18214 — Not Vulnerable These flaws were resolved in older releases of the library. The version deployed with WCC 12.1.x (2.23.0) already includes the necessary upstream fixes for these two vulnerabilities.

  • CVE-2022-24785 and CVE-2022-31129 — Version Affected, but Not Exploitable Although version 2.23.0 falls within the version window flagged by scanners for these vulnerabilities, they cannot be exploited in WCC. To exploit these CVEs, an attacker must have a vector to pass malicious, untrusted input into specific moment.js functions. Within the WCC QuickView application framework, moment.js is strictly used to render and format the current system time on the display interface—no user input or external parameters are ever passed to it. Consequently, there is no path for an attacker to trigger the vulnerabilities.

Version Context & Remediation Summary:

  • WCC 12.1.x: Out-of-the-box library version is 2.23.0. The application is entirely secure against these CVEs based on library usage implementation. No individual patch is required or provided for 12.1.x.

  • WCC 24.2: This release naturally addresses the version-level scan findings by upgrading the bundled library to moment.js version 2.30.1, which satisfies the NVD-recommended 2.29.4+ threshold.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.